Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
Sudomy preview

Sudomy

GitHubscreetsec/sudomy

Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting /…

dns-analysisinformation-gatheringosint+5
2.4k
2 years ago
awesome-industrial-control-system-security preview

awesome-industrial-control-system-security

GitHubhslatman/awesome-industrial-control-system-security

A curated list of resources related to Industrial Control System (ICS) security.

curated-resourcesexploitationfuzzing+9
2.0k11 months ago
KaliIntelligenceSuite preview

KaliIntelligenceSuite

GitHubchopicalqui/kaliintelligencesuite

Automated intelligence-gathering framework that orchestrates Kali Linux tools and public APIs to collect, store, and analyze reconnaissance data for…

information-gatheringosintpenetration-testing+3
994 years ago
ipv4Bypass preview

ipv4Bypass

GitHubmilo2012/ipv4bypass

Using IPv6 to Bypass Security

ids-ips-evasionnetwork-securitypenetration-testing+2
931 year ago
joomla-cve-2018-6396 preview

joomla-cve-2018-6396

GitHubjavierolmedo/joomla-cve-2018-6396

Joomla - Component Google Map Landkarten <= 4.2.3 - SQL Injection

exploitationinformation-gatheringpenetration-testing+2
88 years ago
CMS-made-simple-sqli-python3 preview

CMS-made-simple-sqli-python3

GitHubxtafnull/cms-made-simple-sqli-python3

CMS Made Simple < 2.2.10 - SQL Injection (rewritten for python3), CVE-2019-905

exploitationpenetration-testingvulnerability-analysis+1
4 years ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationexploitationosint+8
1196 days ago
CVE-2026-42945_NginxRift preview

CVE-2026-42945_NginxRift

GitHubkentox493/cve-2026-42945_nginxrift

Automates CVE-2026-42945 exploitation in NGINX containers: verifies vulnerable targets, brute-forces heap offsets, executes commands, and opens an…

binary-exploitationcontainer-securityctf+5
11 month ago
Vanquish preview

Vanquish

GitHubfrizb/vanquish

Vanquish is Kali Linux based Enumeration Orchestrator. Vanquish leverages the opensource enumeration tools on Kali to perform multiple active…

dns-subdomain-enumerationexploitationinformation-gathering+8
5148 years ago
COPY-FAIL-Detection-with-Wazuh-4.14.4 preview

COPY-FAIL-Detection-with-Wazuh-4.14.4

GitHubmym0us3r/copy-fail-detection-with-wazuh-4.14.4

Wazuh 4.14.4 detection rules for CVE-2026-31431 (Copy Fail) - Linux Local Privilege Escalation via authencesn page cache write

configuration-auditingintrusion-detectionprivilege-escalation+2
94 months ago
network-security-snort preview

network-security-snort

GitHubtaisa456/network-security-snort

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…

defensive-toolseducationexploitation+6
4 months ago
TP-Link-Archer-CR-700-XSS-Exploit preview

TP-Link-Archer-CR-700-XSS-Exploit

GitHubayushman4/tp-link-archer-cr-700-xss-exploit

Exploiting TP-Link Archer CR-700 Router. (Responsibly Disclosed to TP-Link)

exploitationiot-securitypenetration-testing+3
310 years ago
CyberSecurity-Pentest-Lab preview

CyberSecurity-Pentest-Lab

GitHubgermarr93/cybersecurity-pentest-lab

CVE-2004-2687 (Distcc 3.2.1) exploitation, methodology & remediation — Metasploitable2 lab

ctfeducationexploitation+6
14 days ago
Log4Shell-CVE-2021-44228 preview

Log4Shell-CVE-2021-44228

GitHubdrhaitham/log4shell-cve-2021-44228

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and…

command-and-controleducationexploitation+7
9 months ago
WSS preview

WSS

GitHubnu11secur1ty/wss

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

code-analysisinformation-gatheringpassword-attacks+3
33 months ago
CVE-2024-9264-in-Grafana-11.x preview

CVE-2024-9264-in-Grafana-11.x

GitHubbarun121/cve-2024-9264-in-grafana-11.x

Vulnerability Exploitation using tools Penetration Testing, Grafana, Docker, Kali Linux.

cloud-infrastructure-securityexploitationpenetration-testing+2
1 month ago
CVE-2021-4034-NoGCC preview

CVE-2021-4034-NoGCC

GitHubestamelgg/cve-2021-4034-nogcc

Standalone exploit for CVE-2021-4034 (polkit pkexec) that runs without gcc or cmake, providing interactive shell or one-liner command execution on…

exploitationexploit-frameworkspenetration-testing+2
784 years ago
HFS_EXPLOIT_PROJECT preview

HFS_EXPLOIT_PROJECT

GitHubsage954526/hfs_exploit_project

Metasploit RCE on HFS 2.3 - CVE-2014-62

educationexploit-frameworkspenetration-testing+3
1 year ago
Previous12Next